Line illustration showing a black application window on a dark black to purple gradient background overlaid with a large exclamation point alert icon and three bugs.

WordPress Vulnerability Report � January 1, 2025

In this report, 81 vulnerabilities have been publicly disclosed. Security patches for 75 of these plugins are available now, so run those updates as soon as possible. If you’re a Solid Security Pro user, the version management tool may have already warned you and updated these plugins, depending on your settings.

Additionally, there are 6 plugin vulnerabilities with no patch available yet. If you’re a Solid Security Pro user, those vulnerabilities are already protected by the Solid Security firewall. Virtual patches from Patchstack will be applied when a vulnerability is considered high or medium risk. If no patch is forthcoming from the vendor or the vulnerable software has been marked “closed” and dropped from the official WordPress repositories, you should deactivate it soon and look for alternative solutions.

WordPress Core

WordPress 6.7.1 is available! This minor release features 16 bug fixes throughout Core and the Block Editor.

WordPress Plugins � 75 Patched / 6 Unpatched

WP-SVG

Plugin:

WP-SVG

Plugin Slug:
wp-svg

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.
Plugin Slug:
exhibit-to-wp-gallery

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

float block

Plugin Slug:
float-block

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

GTPayment Donations

Plugin:

GTPayment Donations

Plugin Slug:
gtpayment-donation

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
No Fix

Severity Score:
High


The vulnerability has not been patched. You should deactivate the plugin.

WP Publications

Plugin:

WP Publications

Plugin Slug:
wp-publications

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
No Fix

Severity Score:
Medium


The vulnerability has not been patched. You should deactivate the plugin.

Jetpack � WP Security, Backup, Speed, & Growth

Plugin Slug:
jetpack

Installations
4,000,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
14.1-a.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 14.1-a.1.
Plugin Slug:
broken-link-checker

Installations
600,000+

Vulnerability:
Server Side Request Forgery (SSRF)

Patched in Version:
2.4.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.2.

Advanced Google reCAPTCHA

Plugin Slug:
advanced-google-recaptcha

Installations
100,000+

Vulnerability:
Other Vulnerability Type

Patched in Version:
1.26

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.26.

Tracking Code Manager

Plugin Slug:
tracking-code-manager

Installations
100,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.4.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.0.

Print Invoice & Delivery Notes for WooCommerce

Plugin Slug:
woocommerce-delivery-notes

Installations
30,000+

Vulnerability:
Broken Access Control

Patched in Version:
5.4.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.4.1.

Data Tables Generator by Supsystic

Plugin Slug:
data-tables-generator-by-supsystic

Installations
20,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.10.37

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.10.37.

Post Grid Elementor Addon

Plugin Slug:
post-grid-elementor-addon

Installations
20,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.19

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.19.

AyeCode Connect

Plugin Slug:
ayecode-connect

Installations
10,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.9.

WordPress Simple Shopping Cart

Plugin Slug:
wordpress-simple-paypal-shopping-cart

Installations
10,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.0.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.8.

WP Post Author � Boost Your Blog’s Engagement with Author Box, Social Links, Co-Authors, Guest Authors, Post Rating System, and Custom User Registration Form Builder

Plugin Slug:
wp-post-author

Installations
10,000+

Vulnerability:
SQL Injection

Patched in Version:
3.8.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.8.3.

WP Datepicker

Plugin Slug:
wp-datepicker

Installations
9,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.5

Severity Score:
High


The vulnerability has been patched, so you should update to version 2.1.5.

Arconix Shortcodes

Plugin Slug:
arconix-shortcodes

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.15

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.15.

WPKoi Templates for Elementor

Plugin Slug:
wpkoi-templates-for-elementor

Installations
5,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
3.1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.1.4.

Booking calendar, Appointment Booking System

Plugin Slug:
booking-calendar

Installations
4,000+

Vulnerability:
SQL Injection

Patched in Version:
3.2.20

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.2.20.

Responsive Blocks � WordPress Gutenberg Blocks

Plugin Slug:
responsive-block-editor-addons

Installations
4,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.9.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.9.8.

Ashe Extra

Plugin Slug:
ashe-extra

Installations
3,000+

Vulnerability:
Broken Access Control

Patched in Version:
1.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.

Move Addons for Elementor

Plugin Slug:
move-addons

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.3.7

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.3.7.

WP-Appbox

Plugin Slug:
wp-appbox

Installations
3,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
4.5.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.5.4.

Premium Blocks � Gutenberg Blocks for WordPress

Plugin Slug:
premium-blocks-for-gutenberg

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.43

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.43.

Pronamic Google Maps

Plugin Slug:
pronamic-google-maps

Installations
2,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.3.3

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.3.3.

WC Price History for Omnibus

Plugin Slug:
wc-price-history

Installations
2,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.4

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.4.

ELEX WooCommerce Dynamic Pricing and Discounts

Plugin Slug:
elex-woocommerce-dynamic-pricing-and-discounts

Installations
1,000+

Vulnerability:
Broken Access Control

Patched in Version:
2.1.8

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.8.

Themify Audio Dock

Plugin Slug:
themify-audio-dock

Installations
1,000+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.5

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.5.

ConvertCalculator for WordPress

Plugin Slug:
convertcalculator

Installations
900+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.2.

Event Espresso � Event Registration & Ticketing Sales

Plugin Slug:
event-espresso-decaf

Installations
900+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
5.0.31.decaf

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.0.31.decaf.

Hestia Nginx Cache

Plugin Slug:
hestia-nginx-cache

Installations
800+

Vulnerability:
Broken Access Control

Patched in Version:
2.4.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.4.1.

Just Writing Statistics

Plugin Slug:
just-writing-statistics

Installations
800+

Vulnerability:
SQL Injection

Patched in Version:
4.8

Severity Score:
High


The vulnerability has been patched, so you should update to version 4.8.

WPMasterToolKit (WPMTK) � All in one plugin

Plugin Slug:
wpmastertoolkit

Installations
800+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.14.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 1.14.0.

WPMasterToolKit (WPMTK) � All in one plugin

Plugin Slug:
wpmastertoolkit

Installations
800+

Vulnerability:
Arbitrary File Download

Patched in Version:
1.14.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.14.0.

Loan Comparison

Plugin Slug:
loan-comparison

Installations
500+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.0.1.

WP on AWS

Plugin Slug:
wp-migrate-2-aws

Installations
400+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.2.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 5.2.2.

ACF City Selector

Plugin Slug:
acf-city-selector

Installations
200+

Vulnerability:
Arbitrary File Upload

Patched in Version:
1.15.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.15.0.

Export Customers Data

Plugin Slug:
export-customers-data

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.4

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.2.4.

NinjaTeam Chat for Telegram

Plugin Slug:
ninjateam-telegram

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.

ShMapper by Teplitsa

Plugin Slug:
shmapper-by-teplitsa

Installations
200+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.5.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.5.0.

Bitcoin Lightning Publisher for WordPress

Plugin Slug:
bitcoin-lightning-publisher

Installations
100+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.4.2

Severity Score:
High


The vulnerability has been patched, so you should update to version 1.4.2.

Interactive UK Map

Plugin Slug:
interactive-uk-map

Installations
100+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
3.4.9

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.4.9.

Optio Dentistry

Plugin Slug:
optio-dentistry

Installations
70+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.2.

DN Shipping by Weight for WooCommerce

Plugin Slug:
dn-shipping-by-weight

Installations
60+

Vulnerability:
Cross Site Request Forgery (CSRF)

Patched in Version:
1.2

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.

GS Shots for Dribbble

Plugin Slug:
gs-dribbble-portfolio

Installations
30+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.2.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.2.1.

GS Coaches

Plugin Slug:
gs-coach

Installations
10+

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
1.1.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.1.1.

Advanced Floating Content

Plugin:

Advanced Floating Content

Plugin Slug:
advanced-floating-content

Vulnerability:
SQL Injection

Patched in Version:
3.8.3

Severity Score:
High


The vulnerability has been patched, so you should update to version 3.8.3.

Coins MarketCap

Plugin:

Coins MarketCap

Plugin Slug:
coins-marketcap

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
5.5.9

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 5.5.9.

Floating Action Buttons

Plugin Slug:
floating-action-buttons

Vulnerability:
Broken Access Control

Patched in Version:
1.0.1

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 1.0.1.

Fusion Builder

Plugin:

Fusion Builder

Plugin Slug:
fusion-builder

Vulnerability:
Broken Access Control

Patched in Version:
3.11.13

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 3.11.13.

ShopElement

Plugin Slug:
shopelement

Vulnerability:
Cross Site Scripting (XSS)

Patched in Version:
2.1.0

Severity Score:
Medium


The vulnerability has been patched, so you should update to version 2.1.0.

WooCommerce Point of Sale

Plugin:

WooCommerce Point of Sale

Plugin Slug:
woo-point-of-sale

Vulnerability:
Insecure Direct Object References (IDOR)

Patched in Version:
6.2.0

Severity Score:
Critical


The vulnerability has been patched, so you should update to version 6.2.0.

WordPress Themes � 0 Patched / 0 Unpatched

Related articles

Wait! Get exclusive hosting insights

Subscribe to our newsletter and stay ahead of the competition with expert advice from our hosting pros.

Loading form…